Courseiva
Secure networking →easyMultiple Choice

Enabling NSG Flow Logs and Traffic Analytics for Network Monitoring

A security team needs to analyze network traffic to and from Azure virtual machines to investigate a potential security incident. They want to capture information such as source IP, destination IP, port, and protocol. Which Azure service should they enable on the network security groups (NSGs) associated with the virtual machine subnets?

⚠ Common exam trap

Many exam-takers confuse Traffic Analytics (a visualization/analysis layer) with the underlying data capture mechanism (NSG flow logs), or mistakenly think Azure Monitor logs or Azure Firewall logs provide the same subnet-level flow data without additional configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network Watcher NSG flow logs

Network Watcher NSG flow logs capture IP traffic flowing through Network Security Groups, recording source IP, destination IP, port, and protocol for each flow. This directly meets the requirement to analyze network traffic to and from Azure VMs for security incident investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network Watcher NSG flow logs

    Why this is correct

    NSG flow logs are the definitive source for IP-level traffic to/from VMs because they record the five-tuple (source IP, destination IP, source port, destination port, protocol) and the allow/deny action for every flow tested against the NSG. Unlike broad resource logs, these logs are specifically designed to answer 'who talked to whom' at the network layer, making them indispensable for security investigations. They capture both direction and state, so the team can trace the exact packets that were permitted or refused.

  • ✗

    Azure Monitor logs

    Why it's wrong here

    Azure Monitor logs aggregate metrics, activity logs, and resource diagnostics from Azure services, but they do not natively contain the per-flow IP records produced by NSG flow logs. To store and query those flow records, you must explicitly configure NSG flow logs to ship to a storage account or a Log Analytics workspace, and then use Azure Monitor to analyze them. Simply enabling Azure Monitor does not give an organization the raw flow data; it only serves as a downstream analytics platform once the data is routed to it.

  • ✗

    Traffic Analytics

    Why it's wrong here

    Traffic Analytics is an add-on to Network Watcher that visualizes and summarizes NSG flow logs, offering dashboards with top talkers, denied traffic, and geographic flows. It does not capture or store the underlying flow data itself; it relies on NSG flow logs being already sent to a Log Analytics workspace. Therefore, if flow logs are not enabled, Traffic Analytics has no data to analyze, making it a post-processing tool rather than a data source.

  • ✗

    Azure Firewall logs

    Why it's wrong here

    Azure Firewall logs record traffic that actually passes through the Azure Firewall service, which is only present in a specific subnet and only sees traffic that is route-forced to it. Many VMs use network security groups (NSGs) instead of a firewall, so traffic to and from those VMs would never appear in firewall logs. Even when a firewall is present, NSG flow logs are still needed to cover the full subnet-level activity, because firewall logs omit traffic that is denied by an NSG before it reaches the firewall.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.